[issue2586] Integer signedness bugs in zlib modules

Justin Ferguson report at bugs.python.org
Tue Apr 8 17:41:40 CEST 2008


New submission from Justin Ferguson <justin.ferguson at ioactive.com>:

The zlib module in multiple places fails to adequately check the sanity
of its arguments resulting in memory corruption, please see two attached
PoCs.

----------
components: Extension Modules
files: python-2.5.2-zlib-unflush-misallocation.py
messages: 65171
nosy: jnferguson
severity: normal
status: open
title: Integer signedness bugs in zlib modules
type: security
versions: Python 2.5
Added file: http://bugs.python.org/file9983/python-2.5.2-zlib-unflush-misallocation.py

__________________________________
Tracker <report at bugs.python.org>
<http://bugs.python.org/issue2586>
__________________________________


More information about the Python-bugs-list mailing list